Even though the firewall guards the router from the public interface, you should still want to disable RouterOS solutions.The initial rule accepts packets from presently established connections, assuming they are Protected to not overload the CPU. The 2nd rule drops any packet that connection monitoring identifies as invalid. After that, we set up